Erik Johnston

4 exploits Active since Apr 2021
CVE-2021-29431 WRITEUP HIGH WRITEUP
Sydent < 2.3.0 - Server-Side Request Forgery via HTTP GET Request
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration. This issue has been addressed in in 9e57334, 8936925, 3d531ed, 0f00412. A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
CVSS 7.7
CVE-2021-29432 WRITEUP MEDIUM WRITEUP
matrix-sydent < 2.3.0 - Arbitrary Email Spoofing via Identity Server
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
CVSS 5.3
CVE-2024-31208 WRITEUP MEDIUM WRITEUP
Synapse < 1.105.1 - Denial of Service via V2 State Resolution Algorithm
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.
CVSS 6.5
CVE-2025-30355 WRITEUP HIGH WRITEUP
Synapse < 1.127.1 - Denial of Service via Malicious Federation Events
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
CVSS 7.1